CVE-2026-16801: 
Ironman Software PowerShell Universal vulnerability analysis and mitigation

Overview

CVE-2026-16801 is a code injection vulnerability (CWE-94) in the variables feature of Devolutions PowerShell Universal that allows an authenticated user with variable write permission to execute arbitrary PowerShell code. The flaw affects Devolutions PowerShell Universal version 2026.2.2 and earlier (all versions prior to 2026.2.3.0). It was published on July 24, 2026, with a patch advisory released the same day. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, Devolutions Advisory).

Technical details

The root cause is improper neutralization of user-supplied input in the variables feature (CWE-94: Improper Control of Generation of Code). When an authenticated user with variable write permission creates or modifies a variable, the supplied value is written to a variables configuration file without adequate escaping or sanitization. A crafted variable value containing PowerShell code can break out of the expected data context and be interpreted as executable code when the configuration file is subsequently processed by the PowerShell Universal runtime. Exploitation requires network access and a low-privilege authenticated account with variable write permissions — no user interaction or elevated privileges beyond that are needed (GitHub Advisory, Devolutions Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary PowerShell code with the privileges of the PowerShell Universal process, resulting in high impact to confidentiality, integrity, and availability. Depending on the process privilege level, an attacker could exfiltrate sensitive data, modify system configurations, install backdoors, or disrupt service availability. The scope of impact is contained to the affected system, but lateral movement is possible if the PowerShell Universal process has access to other network resources or credentials (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit code known at this time, and no evidence of in-the-wild exploitation has been reported (Devolutions Advisory). The NVD SSVC assessment confirms exploitation status as "none" and notes the attack is not automatable, as it requires an authenticated session with specific variable write permissions. The EPSS score is approximately 0.29% (22nd percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Exploitation steps

  1. Reconnaissance: Identify a Devolutions PowerShell Universal instance running version 2026.2.2 or earlier. Confirm access to the web interface and obtain or compromise credentials for an account with variable write permissions.
  2. Authenticate: Log in to the PowerShell Universal web interface or API using the compromised low-privilege account.
  3. Navigate to Variables: Access the variables management feature within the PowerShell Universal administration interface.
  4. Craft malicious variable value: Create or edit a variable and supply a crafted value containing PowerShell code designed to escape the data context when written to the configuration file (e.g., using quote characters or special syntax to inject a PowerShell command such as "; Start-Process calc.exe; ").
  5. Trigger code execution: Save the variable, causing the crafted value to be written to the variables configuration file without proper escaping. When PowerShell Universal processes or loads the configuration file, the injected code is executed with the privileges of the PowerShell Universal process.
  6. Achieve objective: Use the code execution to establish persistence, exfiltrate data, or pivot to other systems accessible from the PowerShell Universal server (GitHub Advisory, Devolutions Advisory).

Indicators of compromise

  • Logs: Unexpected PowerShell commands or processes appearing in PowerShell Universal application logs; audit log entries showing variable creation or modification by accounts not typically performing such actions.
  • File System: Unusual or recently modified variables configuration files in the PowerShell Universal installation directory containing embedded code-like strings (e.g., semicolons, cmdlet names, or script blocks within variable values).
  • Process: Unexpected child processes spawned by the PowerShell Universal service process (e.g., powershell.exe, cmd.exe, net.exe, curl.exe, or reverse shell utilities).
  • Network: Outbound connections from the PowerShell Universal server to unknown external IP addresses or C2 infrastructure, particularly over uncommon ports.

Mitigation and workarounds

Devolutions has released a patch in PowerShell Universal version 2026.2.3.0, which addresses the improper escaping of variable values written to the configuration file. Organizations should upgrade to version 2026.2.3 or later as the primary remediation step (Devolutions Advisory, GitHub Advisory). As interim workarounds, restrict variable write permissions to only highly trusted users, audit existing variables for suspicious content (e.g., embedded PowerShell syntax), and monitor for unauthorized variable modifications via audit logs.

Community reactions

The vulnerability received brief coverage on social media, including a mention on Mastodon via The Hacker Wire account shortly after disclosure. No significant vendor statements beyond the official Devolutions advisory, nor notable independent researcher commentary or major media coverage, have been identified at this time.

Additional resources


Source: This report was generated using AI

Related Ironman Software PowerShell Universal vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-16801HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-16800HIGH8.8
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026
CVE-2026-19768HIGH8.1
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesAug 14, 2026
CVE-2026-92237MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoNoSep 15, 2026
CVE-2026-16802MEDIUM6.5
  • Ironman Software PowerShell Universal logoIronman Software PowerShell Universal
  • cpe:2.3:a:ironmansoftware:powershell_universal
NoYesJul 24, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management